CVE-2009-1251
published 2009-04-09CVE-2009-1251: Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers…
PriorityP348critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.44%
92.9th percentile
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openafs | < openafs 1.4.10+dfsg1-1 (bookworm) | openafs 1.4.10+dfsg1-1 (bookworm) |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
| openafs | openafs | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2xj8-3jr2-7qw3: Heap-based buffer overflow in the cache manager in the client in OpenAFS 1
ghsa_unreviewed·2022-05-02
CVE-2009-1251 [HIGH] CWE-119 GHSA-2xj8-3jr2-7qw3: Heap-based buffer overflow in the cache manager in the client in OpenAFS 1
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
OSV
CVE-2009-1251: Heap-based buffer overflow in the cache manager in the client in OpenAFS 1
osv·2009-04-09·CVSS 10.0
CVE-2009-1251 [CRITICAL] CVE-2009-1251: Heap-based buffer overflow in the cache manager in the client in OpenAFS 1
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
Debian
CVE-2009-1251: openafs - Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 thr...
vendor_debian·2009·CVSS 10.0
CVE-2009-1251 [CRITICAL] CVE-2009-1251: openafs - Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 thr...
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
Scope: local
bookworm: resolved (fixed in 1.4.10+dfsg1-1)
bullseye: resolved (fixed in 1.4.10+dfsg1-1)
sid: resolved (fixed in 1.4.10+dfsg1-1)
trixie: resolved (fixed in 1.4.10+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/34655http://secunia.com/advisories/34684http://secunia.com/advisories/42896http://security.gentoo.org/glsa/glsa-201101-05.xmlhttp://www.debian.org/security/2009/dsa-1768http://www.mandriva.com/security/advisories?name=MDVSA-2009:099http://www.openafs.org/security/OPENAFS-SA-2009-001.txthttp://www.openafs.org/security/openafs-sa-2009-001.patchhttp://www.securityfocus.com/bid/34407http://www.vupen.com/english/advisories/2009/0984http://www.vupen.com/english/advisories/2011/0117http://secunia.com/advisories/34655http://secunia.com/advisories/34684http://secunia.com/advisories/42896http://security.gentoo.org/glsa/glsa-201101-05.xmlhttp://www.debian.org/security/2009/dsa-1768http://www.mandriva.com/security/advisories?name=MDVSA-2009:099http://www.openafs.org/security/OPENAFS-SA-2009-001.txthttp://www.openafs.org/security/openafs-sa-2009-001.patchhttp://www.securityfocus.com/bid/34407http://www.vupen.com/english/advisories/2009/0984http://www.vupen.com/english/advisories/2011/0117
2009-04-09
Published